Drill 22 ยท
AP Cybersecurity Drill 22: Classifying Sensitive Records is a practice drill. It contains 5 original questions created by Brian Stewart, a Barron's test prep author with over 20 years of tutoring experience.
A clinic that also runs a training program for student interns sorts its records by data type so each gets the right handling; this drill uses an invented company and original figures.
Vantreel Health Partners is a clinic that also trains student interns. A privacy officer lists four record sets and the fields each one holds, to decide how each must be protected.
| Record set | Fields it contains |
|---|---|
| Set 1: Patient charts | Patient name, diagnosis, prescribed medications, treatment notes |
| Set 2: Billing file | Patient name, credit-card number, card expiration date |
| Set 3: Staff directory | Employee name, work email, office phone extension |
| Set 4: Intern records | Student name, course grades, school enrollment status |
Question 1. Set 1 (patient charts) is best classified as which type of data?
Explanation: Choice B is correct. Protected health information is individually identifiable information about a person's health, care, or treatment; a chart linking a named patient to diagnoses and medications fits squarely. Choice A is incorrect because the chart holds clinical, not payment, data. Choice C is incorrect because a name alongside a diagnosis is far more sensitive than a directory entry. Choice D is incorrect because the chart is about a patient's health, not a student's schooling, even though interns may study it.
Question 2. Looking only at the field type shown, not broader sector-specific legal rules, the most specific classification of Set 2 is:
Explanation: Choice D is correct. A credit-card number with its expiration date is payment-card data, a category of financial data, and it carries direct fraud risk if exposed. Choice A is incorrect because the card data itself is financial, not clinical, even when collected at a clinic. Choice B is incorrect because a directory holds low-sensitivity contact details, not payment cards. Choice C is incorrect because nothing here concerns a school record.
Question 3. Which record set carries the LEAST sensitivity and the lightest handling duty?
Explanation: Choice A is correct. A staff directory of work names, work emails, and office extensions is ordinary business-contact information and is the least sensitive set here. Choice B is incorrect because routine clinician access does not lower how sensitive health data is. Choice C is incorrect because card data is highly sensitive regardless of who bears fraud losses. Choice D is incorrect because student grades and enrollment are still student/education record data, not low-sensitivity data.
Question 4. An auditor reviewing Set 4 wants to confirm it includes academic-performance information. Which single field in Set 4 most directly confirms that?
Explanation: Choice D is correct. Course grades are academic performance information tied to a named student, which is exactly what the question asks the auditor to confirm. Choice A is incorrect because a name appears in every set and reflects identity, not academic performance. Choice B is incorrect because enrollment status is student/education record context but records a standing, not a measure of performance. Choice C is incorrect because a timestamp is metadata present on many records and says nothing about academic performance.
Question 5. Given the mix of data types, what is the best overall protection approach for these four sets?
Explanation: Choice B is correct. Matching the strength of controls to each data class, with tight access and encryption for the sensitive sets and routine internal access only for the low-sensitivity directory, applies protection in proportion to risk. Choice A is incorrect because one open folder ignores the differing sensitivity and over-exposes protected data. Choice C is incorrect because health and student records also require protection, not just card data. Choice D is incorrect because deleting the directory is unjustified and leaves the sensitive sets unaddressed.